Digipass S3 is now DigipassONE. This section is currently being updated to reflect our new name.

Integrating Digipass S3 Authentication for passkeys

Prev Next

Digipass S3 Authentication Cloud provides secure, user-friendly, passwordless authentication for your applications.  

It uses JSON Web Tokens (JWTs) to securely transmit information — information that can be trusted and verified because each token is digitally signed.

Diagram illustrating authentication flow between client device and servers using passkey assertion.

S3 Integration with Passkeys

The diagram above demonstrates how information is exchanged between:

  • an application

  • the application server, and

  • the Digipass S3 Authentication Server

when a user logs in using passkeys or performs an action with an application that requires them to authenticate.  

Overview of Digipass S3 integration

Enabling digital credentials on your application will require both server-side and application-side development, and will generally follow this process:  

Server side

  1. Deploy the Authentication Server
    Customers can request a tenant to be created on the Digipass S3 Authentication Cloud, otherwise they may install the Digipass S3 Authentication Server in their data center and create databases to store user data. The Digipass S3 API Server is also installed  at this time.    

  2. Configure the Authentication Server
    The Authentication Server must be configured to allow users to authenticate using passkeys.    

Application side

Tutorial apps

  1. Learn implementation via the Tutorial Apps
    The Digipass S3 SDKs contain lightweight applications that you can use to learn how to implement passwordless authentication. These Tutorial Apps can also assist you with building your own apps for Android, iOS and web.

  2. Test your implementation
    You can verify if your implementation works by installing the Tutorial App and testing it with:

    • a mobile device using a native app or mobile browser, or

    • a desktop or laptop using a browser.

Your own app

  1. Design the authentication flow
    Decide which policies and criteria you will use for authentication and choose which app operations will require authentication so you can design the best experience for your users.

  2. Integrate passwordless authentication on your own apps
    Once you have completed the above steps, you should be ready to implement passkeys on your own applications.